Accurate guidance for Steel Security Free and Steel Security Pro

Understanding Server Protection

Server Protection reports safe detection signals and, when available, current-state telemetry for host-level tools without asking WordPress to manage them directly.

Server Protection Free Updated August 9, 2026

What this means

Fail2Ban and cPHulk are server-level tools. Steel Security reports what WordPress can safely observe, but it does not require elevated privileges or attempt to control those services.

The safest model is: server tool → root-managed reporter/exporter → sanitized JSON → Steel Security → WordPress admin UI.

Why it matters

Operators often need to know whether host-level protections appear present, active, stale, inaccessible, malformed, disabled, or unsupported without giving a plugin unsafe server power.

What Steel Security checks

Fail2Ban reporter availability, freshness, service state, and per-jail telemetry when a reporter is connected.

cPanel and cPHulk environmental indicators, plus cPHulk current-state telemetry when a root-managed reporter is connected.

Server-level limitations

A plugin running inside WordPress cannot prove everything about server-level protections.

Statuses such as `possible`, `not detected`, `unable to determine`, `stale`, `partial telemetry`, `disabled`, or `malformed` are intentionally cautious.

Free is the right place for current-state reporting. Pro is the right place for retained history, trends, alerting, and deeper operational workflows built on top of the same telemetry.

Continue reading